Security firm Lakera analyzed 10,000 MCP servers and found that roughly 40% have exploitable security weaknesses. Threats include tool poisoning and rug pull attacks, where attackers can manipulate AI agent behavior via malicious instructions. Check Point and other vendors are developing dedicated AI firewalls. MCP, released by Anthropic in November 2024 as an open standard, had over 10,000 active public servers by December 2025, with support from AWS, Google Cloud, and Azure. Major AI platforms like ChatGPT, Gemini, and Microsoft Copilot have adopted the protocol.
Lakera: 40% of MCP Servers Have Exploitable Weaknesses
MCP is fast becoming the go-to standard for AI agents that need to hook into outside tools and data. But that shift brings fresh security trouble. Security firm Lakera looked at 10,000 MCP servers and found that about 40% carry security weaknesses attackers could exploit.
Threat Types: Tool Poisoning and Rug Pull Attacks
OWASP says the threats aimed at MCP servers include tool poisoning and rug pull attacks. Bad actors can slip malicious instructions into tool descriptions or return values, then use them to steer AI agent behavior. And cybersecurity vendors such as Check Point are building specialized AI firewalls to push back on these new threats.
Background of the MCP Standard
Anthropic released MCP in November 2024 as an open standard. By December 2025, more than 10,000 public servers were active, and AWS, Google Cloud, and Azure all supported it. Big AI platforms including ChatGPT, Gemini, and Microsoft Copilot, plus coding assistants, have already adopted the protocol.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.